CVE-2026-15326: halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such manipulation of the argument metadata.name leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The project closed the issue as "duplicate" but did not reference any other issue, report, or CVE.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
halo-dev halo Theme Installation (ThemeUtils.unzipThemeTo)to a version that resolves this vulnerability.Fixed in 2.24.2 - Compensating control
Since the exploit is publicly available and may be launched remotely, restrict network access to the Halo instance (management/UI) to trusted sources only (e.g., via firewall/IP allowlist) until the upgrade is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15326?
The severity of CVE-2026-15326 is categorized as low with a score of 3.8.
What type of vulnerability is CVE-2026-15326?
CVE-2026-15326 is classified as a path traversal vulnerability.
How can CVE-2026-15326 be exploited?
CVE-2026-15326 can be exploited remotely through manipulation of the argument metadata.name in the ThemeUtils.unzipThemeTo function.
How do I fix CVE-2026-15326?
To fix CVE-2026-15326, it is recommended to update the halo-dev halo theme to version 2.24.3 or later.
In which software is CVE-2026-15326 found?
CVE-2026-15326 is found in the halo-dev halo theme versions up to 2.24.2.